← All actors Recent activity

Daggerfly G1034

EVASIVEPANDA · Bronze Highland · Daggerfly

Indicators
14
Source reports
17
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20202025

Overview 14 indicators

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.

ipv411G1034.json
domain3G1034-domain.txt

Techniques 17 ATT&CK

Open in ATT&CK Navigator → or download the layer (17 techniques, layer 4.5)

Software 6

Principal sources 17 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 14 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 1 ipv41 yr ago

    x.com/TuringAlex/status/1859969605084823621 · bleepingcomputer.com/news/security/chinese-cyberspies-use-ne… · virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…

    45.125.64.200:33200

  2. 3 ipv42 yrs ago

    x.com/TuringAlex/status/1859969605084823621 · bleepingcomputer.com/news/security/chinese-cyberspies-use-ne… · virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…

    223.165.4.175:81
    45.125.64.200:33220
    45.125.64.200:33223

  3. 4 ipv42 yrs ago

    symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage… · virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f… · virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6e… · virustotal.com/gui/file/23acab55f533cad2471516d15f52a8… · virustotal.com/gui/file/dfd28fa39cfa6a8e06ea897a6df78f… · virustotal.com/gui/file/a0b125e69a8b3619b372fe363bd2cf… · virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4d… · virustotal.com/gui/file/82a662cc06c49714efd8ed9086e201…

    103.96.128.44:10001
    103.96.128.44:16564
    103.96.131.150:19876
    103.96.131.150:40020

  4. 1 domain2 yrs ago

    welivesecurity.com/en/eset-research/evasive-panda-leverage…

    update.devicebug.com

  5. 1 ipv46 yrs ago

    twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…

    45.77.140.81:81

  6. 1 domain, 2 ipv46 yrs ago

    twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…

    domaingovernmentmm.com
    ipv4122.10.89.170:9552
    ipv4122.10.89.172:10560

  7. 1 domain6 yrs ago

    twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…

    flash.governmentmm.com

Further reading 20